“I got a new phone” tickets
As an MSP supporting multiple SMB clients on Okta, you've handled this ticket more times than you can count: a user gets a new phone, and their authenticator is suddenly empty. Okta Verify accounts could already be moved, but every third-party code—GitHub, AWS, Google, and the rest—often had to be re-enrolled by hand, one service at a time. Multiply that across every client you support, each with its own set of users, and "new phone day" becomes a recurring drain on your service desk.
What changed in Okta Verify v9.70.0 for iOS
Okta Verify has supported device-to-device Bluetooth transfer of native Okta Verify accounts for a while. Version 9.70.0 for iOS expands that transfer to also include:
Third-party TOTP accounts – GitHub, AWS, Google, and similar services.
Device Access codes – used for desktop features like Okta Device Access and Platform SSO.
So a full iPhone-to-iPhone move can now bring across all three in a single pass, with no manual re-enrollment of each service.
Understanding the scope of the change
This expansion is iOS-to-iOS only. If either device is Android, macOS, or Windows, you can still transfer native Okta Verify accounts over Bluetooth, but not third-party TOTP or Device Access codes. Those still require the usual re-enrollment on non-iOS moves. Worth knowing before you set a client's expectations.
Why this fits the way we tell you to run MFA
Here's the part we like: the transfer happens directly between the two devices over Bluetooth—nothing syncs through a personal cloud account. That matters, because the reason Okta Verify doesn't offer consumer-style cloud backup is a deliberate security decision: keeping MFA secrets device-bound and out of personal Google, Apple, or Microsoft accounts that could be phished. This feature closes a real convenience gap without reopening that risk. You get the easier upgrade path and the enterprise-grade posture your security-conscious clients—and their auditors—expect.
What to do about it
Make sure Okta Verify is on the latest version on both devices before any iPhone upgrade.
Confirm Okta FastPass is enabled and the account is error-free. Both are prerequisites for transfer.
Update your internal "new phone" runbook so techs use Bluetooth transfer on iOS-to-iOS moves instead of manual re-enrollment.
Want help standardizing device-change workflows across every client from one console? Talk to an Okta-certified expert (who isn't in sales).